Results 1 to 7 of 7
  1. #1
    Experienced User
    Overall activity: 0%

    Join Date
    Mar 2009
    Location
    Australia
    Posts
    955
    Liked
    3 times
    Points
    16,081

    Post Suspect of a worm

    I did a hijackthis scan and there was 1 item was suspicous looks like a worm.here is the log
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:21:22 PM, on 18/04/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\Program Files\DigitalPersona\Bin\DpAgent.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
    C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\FlashGet Network\Flashget 3\flashget3.exe
    G:\hijackthis\HijackThis.exe

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: flashget2 urlcatch - {1F364306-AA45-47B5-9F9D-39A8B94E7EF1} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\kevin\AppData\Roaming\FlashGetBHO\FlashGetBHO3.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
    O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O8 - Extra context menu item: 使用快车3下载 - C:\Users\kevin\AppData\Roaming\FlashGetBHO\GetUrl.htm
    O8 - Extra context menu item: 使用快车3下载全部链接 - C:\Users\kevin\AppData\Roaming\FlashGetBHO\GetAllUrl.htm
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O13 - Gopher Prefix:
    O15 - ESC Trusted Zone: http://*.update.microsoft.com
    O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{39B8DDC8-CBCD-4A2A-9B75-D9E924035A35}: NameServer = 67.138.54.100,208.67.222.222
    O17 - HKLM\System\CS1\Services\Tcpip\..\{39B8DDC8-CBCD-4A2A-9B75-D9E924035A35}: NameServer = 67.138.54.100,208.67.222.222
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe
    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
    O23 - Service: ANSAV Guard (ANSAVDaemon) - Unknown owner - G:\ANSAV\ansavd.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: BitDefender Arrakis Server (Arrakis3) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Contrl Center of Storm Media (ccosm) - 北京暴风网际科技有限公司 - C:\Program Files\StormII\stormliv.exe
    O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
    O23 - Service: Biometric Authentication Service (DpHost) - DigitalPersona, Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:\Windows\system32\Hpservice.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
    O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\MapleStory\npkcmsvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
    O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
    O23 - Service: Recovery Service for Windows - Unknown owner - C:\Windows\SMINST\BLService.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe
    O23 - Service: Validity Fingerprint Service (vfsFPService) - Validity Sensors, Inc. - C:\Windows\system32\vfsFPService.exe
    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
    And this thing looks suspicious
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    if i have any other virus or spyware.please tell me.Dont worry about those chinese programs.
    any help will be appreciated

  2. #2
    Newbie
    Overall activity: 0%

    Join Date
    Aug 2008
    Posts
    29
    Liked
    0 times
    Points
    3,186
    It's a part of AVG 8.5, they now include a Linkscanner also known as WormRadar.com It seems to be left over remains from AVG, which you uninstalled, and now use BitDefender...Good move IMO too
    Last edited by 333halfevil; 04-18-2009 at 08:47 PM.

  3. #3
    Senior Techie
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    UK/ Midlands
    Posts
    207
    Liked
    0 times
    Points
    3,649
    As above left over from AVG

    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

  4. #4
    Star
    Overall activity: 31.0%

    Join Date
    Apr 2009
    Location
    Utah, USA
    Posts
    554
    Liked
    144 times
    Points
    11,795
    Yeah wormradar is part of AVG I used to see that when I had AVG IS, your files look clean.
    MBAM Pro | MSE | www.utahphotographyblog.com

  5. #5
    Experienced User
    Overall activity: 0%

    Join Date
    Mar 2009
    Location
    Australia
    Posts
    955
    Liked
    3 times
    Points
    16,081
    THx.But i just used kaspersky remvoal tool and it detected bit defender as trojan????

  6. #6
    Malware Removal Expert
    Overall activity: 7.0%

    Join Date
    Oct 2008
    Location
    Tulsa, OK
    Posts
    389
    Liked
    12 times
    Points
    5,046
    Quote Originally Posted by muaan View Post
    THx.But i just used kaspersky remvoal tool and it detected bit defender as trojan????
    Antivirus don't play well together. You need to uninstall either BitDefender or AVG.

    [url=http://www.microsoft.com/uk/athome/security/protect/antivirus.mspx]Microsoft, [url=http://www.kaspersky.com/faq?chapter=170704655&qid=169326413]Kaspersky and [url=http://service1.symantec.com/SUPPORT/nav.nsf/docid/2000031316555206]Symantec recommend that you do not have more than one antivirus product installed and running on your computer at the same time.

    The real-time protection of two antivirus programs may conflict with each other and cause the following:

    * False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
    * Conflicts: Your system may lock up due to both products attempting to access the same file at the same time.
    * Performance: More that one antivirus will cause your PC to become slow and it may even crash or blue screen.
    * Less protection: Two antivirus trying to scan the same file may interfere with the process and allow a malicious file onto the computer without notice to you.

  7. #7
    Experienced User
    Overall activity: 0%

    Join Date
    Mar 2009
    Location
    Australia
    Posts
    955
    Liked
    3 times
    Points
    16,081
    ok..Thx for your help
    http://small-anime.blogspot.com/ for my latest 60Mb Mini Mkv's encodes/uploads

 

 

Similar Threads

  1. Replies: 4
    Last Post: 07-24-2011, 08:02 AM
  2. 'LulzSec suspect' arrested by New Scotland Yard !!!
    By INDRANIL in forum Spyware/Viruses
    Replies: 2
    Last Post: 06-23-2011, 09:31 AM
  3. Suspect of virus
    By Kazemagic in forum Spyware/Viruses
    Replies: 15
    Last Post: 05-17-2009, 08:26 PM
  4. Replies: 16
    Last Post: 04-16-2009, 10:42 AM
  5. Rogue/Suspect Anti-Spyware Products & Websites
    By Solaris in forum Spyware/Viruses
    Replies: 4
    Last Post: 08-11-2008, 02:54 AM
All times are GMT +8. The time now is 09:35 AM.