PDA

View Full Version : No scan results in anti-spyware programs; what's going on here?



Josh7289
2009-03-07, 03:27
Hi all,

I'm running the Windows 7 beta.

So I was browsing some questionable sites last night and came across some really questionable material that may have been entirely illegal and quite disgusting (see where I'm going?), so I felt like I really needed to purge my system after seeing that.

I cleared out all my browser caches, etc., first of all. I wasn't running any anti-malware whatsoever besides Windows Defender (no anti-virus, no anti-spyware, etc.), so I quickly downloaded and installed AVG free edition, Spybot, and AdAware, updated them all to the latest versions, and then scanned the hell out of my machine.

The order I scanned was: AVG, then Spybot, then AdAware, then Windows Defender, then I defragmented my hard drive for the hell of it. Well, even though I used the maximum detection settings on everything (for example, in "File Sets" for Spybot I made sure everything was checked), none of my scanners came up with any results whatsoever. Nothing. They all said my machine was perfectly clean.

This sounds like a good thing, but I've never had this happen before on any previous machine (though this is my first time scanning my Windows 7 machine). At the very least I expected Spybot and AdAware to pick up some tracking cookies, but there were no results whatsoever. Maybe this is just because Windows 7 is that good? I doubt it...

Anyway, I shut down my PC after doing those scans last night and just now today tried to start it back up... but that didn't work so well. After going through a bunch of Startup Repair business and problems, I eventually booted up into a working version of Windows 7; however, this restore point that I seem to have booted from no longer has AVG, Spybot, or AdAware installed.

So just now I downloaded, installed, and ran HijackThis, and this is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:07:00 PM, on 3/6/2009
Platform: Unknown Windows (WinNT 6.01.2904)
MSIE: Internet Explorer v8.00 (8.00.7000.0000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://atlantica.ndoorsgames.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: CallWave.lnk = C:\Program Files (x86)\CallWave\IAM.exe
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate1c9875a7a7f043f) (gupdate1c9875a7a7f043f) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6239 bytes





I'm going to re-download Spybot right now and do a scan with that, but please tell me what you think of my HijackThis log.

Thank you very much.

shelf life
2009-03-08, 23:22
hi,

HJT log looks ok as far as i can tell. You should rely on your AV and antimalware results first. I think that apps that run on vista will run on Windows 7, cant say with 100% certainty. Windows 7 as you know is still in beta so your problems may be resulting from a unstable environment.

Josh7289
2009-03-09, 01:22
Well, my anti-virus and anti-malware programs showed absolutely no results, which is what worries me. Maybe the viruses/malware are able to conceal themselves from my scans?

Also, I'm actually experiencing no more obvious problems, but I'm just afraid that maybe there's some proxy set up on my PC now, or something like that, that could be using my machine to upload illicit material.



By the way, is it common for viruses or malware to infect regular files, like my docs and jpgs? I'm a little afraid to transfer any of my files on this machine to any other machines...

shelf life
2009-03-09, 02:33
showed absolutely no results
that does seem rather strange, not even a cookie or two.

This is from the FAQ about W7:

"Yes. While the Windows 7 Beta is stable and has been thoroughly tested, it’s not the finished product. Your computer could crash and you could lose important files. So please don’t beta test Windows on your primary PC.

Other problems you might encounter include:

Software that doesn’t install or work correctly, including anti-virus or security programs

Printers, video cards, or other hardware that doesn’t work

Problems accessing corporate or home networks

Files may become corrupted

Bottom line: Please carefully balance the risks and rewards for you of trying out the Windows 7 Beta before you install. Before installing and using the Beta, download and review the Release notes. They provide important information that you should know before installing and using Windows 7. You should familiarize yourself with all of the known issues in this document prior to installing the software. For example, the release notes describe a bug in which MP3 files may become corrupted and provide information on mitigating risk."

I am using the trial version of Kaspersky which does work on W7 beta.

Josh7289
2009-03-09, 19:30
AVG Free, which is supposed to work on Windows 7, came up with no results, so I'm probably safe, but can anyone see anything wrong with my HJT log?

shelf life
2009-03-10, 00:14
hjt log looks ok as far as I can tell.