SDFix and HJT
SDFix: Version 1.69
Run by administrator - Sat 03/03/2007 @ 16:02:34.77
Microsoft Windows 2000 [Version 5.00.2195]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Entries
Restoring Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINNT\system32\ifconfig.exe - Deleted
C:\WINNT\system32\rtvcscan.exe - Deleted
C:\WINNT\system32\TFTP2928 - Deleted
C:\WINNT\Temp\removalfile.bat - Deleted
ADS Check:
C:\WINNT\system32
No streams found.
Final Check:
Remaining Services:
------------------
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes :
C:\Documents and Settings\jianquin.lu.old\prf102.tmp
C:\Documents and Settings\jianquin.lu.old\prf20.tmp
C:\Documents and Settings\jianquin.lu.old\prf30.tmp
C:\Documents and Settings\jianquin.lu.old\prf7A.tmp
C:\Documents and Settings\jianquin.lu.old\prf9F.tmp
C:\Documents and Settings\jianquin.lu.old\prfAD.tmp
C:\Documents and Settings\jianquin.lu.old\prfCD.tmp
C:\WINNT\Temp\OLD283.tmp
C:\WINNT\Temp\OLD284.tmp
C:\WINNT\Temp\OLD2F1.tmp
C:\WINNT\Temp\OLD2F2.tmp
C:\WINNT\Temp\OLD51.tmp
C:\WINNT\Temp\OLD52.tmp
C:\WINNT\Temp\OLD7F.tmp
C:\WINNT\Temp\OLD80.tmp
C:\WINNT\Temp\OLD92.tmp
C:\WINNT\Temp\OLD93.tmp
C:\WINNT\Temp\OLD99.tmp
C:\WINNT\Temp\OLD9A.tmp
C:\WINNT\Temp\OLDD.tmp
C:\WINNT\Temp\OLDE.tmp
Add/Remove Programs List:
Adaptec Easy CD Creator 4
Adobe Acrobat 5.0
Adobe Shockwave Player
ATI Win2k Display Driver
AVG Anti-Spyware 7.5
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon G.726 WMP-Decoder
Chinese keywords
Canon Camera Support Core Library
Canon Utilities EOS Utility
EPSON Printer Software
Formatter Plus V1.4
HijackThis 1.99.1
Canon Utilities RemoteCapture 2.7
Canon RemoteCapture Task for ZoomBrowser EX
Canon Camera TWAIN Driver 6.0
Canon Utilities File Viewer Utility 1.3
iPod Updater 2004-08-06
Canon Camera TWAIN Driver 6.6
Canon Utilities PhotoStitch 3.1
LiveUpdate 2.6 (Symantec Corporation)
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Internet Explorer Q903235
Quest Software TOAD Professional Edition 7.6
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Shockwave
Adobe Flash Player 9 ActiveX
Update Rollup 1 for Windows 2000 SP4
Microsoft VGX Q833989
Windows 2000 Service Pack 4
WinZip
Canon Utilities ZoomBrowser EX
Microsoft Office 2000 Professional
Database Design Samples
Borders and Backgrounds
Sample Drawings
RemoteCapture 2.7.5
Advanced Network Diagramming Samples
Software Design
RemoteCapture Task
Block Diagrams
Canon Camera TWAIN Driver
File Viewer Utility 1.3.2
Project Schedules
Microsoft Project 2000
iPod Updater 2004-08-06
Symantec AntiVirus
Canon Camera TWAIN Driver
iTunes
Internet Diagrams
QuickTime
Block Diagrams Samples
Flowcharts Samples
Forms and Charts Samples
Shape Explorer Help
VSAdd-in for Internet Explorer
Shape Explorer
Save as HTML
SmartShape Wizard
Database Wizard
Graphics Filters
Visio Core Files
Microsoft Visio Professional 2002 [English]
Microsoft Visio Viewer 2002
DiskeeperWorkstation
Windows 2000 Application Compatibility Update
Apple Software Update
ArcSoft Camera Suite
Internet Diagrams Help
Directory Services Help
Hummingbird Exceed V7.0
Add-ons
Symantec Ghost
VBA
Microsoft Visual Studio Service Pack 3
PhotoStitch
Solutions
Directory Services
Finished
Logfile of HijackThis v1.99.1
Scan saved at 4:30:02 PM, on 3/3/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
C:\Program Files\Symantec\Ghost\ngctw32.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\notepad.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\HijackThis\Scanner.exe.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:80
R3 - URLSearchHook: CnsHook Class - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINNT\DOWNLO~1\CnsHook.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINNT\DOWNLO~1\CnsHook.dll
O4 - HKLM\..\Run: [NGClient] C:\Program Files\Symantec\Ghost\ngctw32.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINNT\DOWNLO~1\CnsMin.dll,Rundll32
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Chinese Keyword - {5D73EE86-05F1-49ed-B850-E423120EC338} -
http://assistant.3721.com/index.htm (file missing)
O9 - Extra button: (no name) - {BF1F4A1A-BDCD-43ac-9D17-261D2C197AB8} -
http://assistant.3721.com/uninstall.htm (file missing)
O9 - Extra button: (no name) - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
http://assistant.3721.com/security1.htm (file missing)
O9 - Extra 'Tools' menuitem: Repair Browser - {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} -
http://assistant.3721.com/security1.htm (file missing)
O9 - Extra button: (no name) - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
http://assistant.3721.com/clean1.htm (file missing)
O9 - Extra 'Tools' menuitem: Clean Internet access record - {FD00D911-7529-4084-9946-A29F1BDF4FE5} -
http://assistant.3721.com/clean1.htm (file missing)
O11 - Options group: [!CNS] Chinese keywords
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = internal.sungard.corp
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = internal.sungard.corp
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = internal.sungard.corp
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\DiskeeperWorkstation\DKService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Inetd\inetd32.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\Program Files\bin\iPodService.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINNT\System32\Hummingbird\Connectivity\7.00\Jconfig\jconfigdNT.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: Symantec Ghost Client Agent (NGClient) - Symantec New Zealand Limited - C:\Program Files\Symantec\Ghost\ngctw32.exe
O23 - Service: OracleOra9ias_homeClientCache - Unknown owner - C:\ora9ias\BIN\ONRSD.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
I got this when I tried to remove the 'junk' using HJT:
SYMANTEC TAMPER PROTECTION ALERT
Target: C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
Event Info: Open Process
Action Taken: Blocked
Actor Process: C:\Documents and Settings\Administrator\Desktop\HijackThis\Scanner.exe.exe (PID 424)
Time: Saturday, March 03, 2007 4:31:47 PM