Interview Question in SQL Server 2008


 

Interview Question :: My Hijackthis log, does anybody understand it


due to my account on a game being hacked i had a feeling i have a keylogger, my friend told me to run a hijackthis log and post it somewhere to get an answer, well ive read it and to me it just looks like coding, i mean its not like the keyloggers gonna jump up and say HELLO IM RIGHT HERE!!!!, so yeah can anyone see anything suspicous in it?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:16:57, on 14/11/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Windows\System32\rundll32.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Common Files\AOL\1201915063\ee\aolsoftware.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22...
C:\Program Files\SPAMfighter\SFAgent.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1...
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDeskto...
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUP...
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSv...
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\dlcxcoms.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F22...
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mc...
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.e...
C:\Windows\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.ex...
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AOL 9.0 VRa\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\AOL 9.0 VRa\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasv...
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Windows\system32\conime.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.e...
C:\Windows\system32\SearchProtocolHost...
C:\Windows\system32\SearchFilterHost.e...
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=6...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_S
Answers to "My Hijackthis log, does anybody understand it"
RE: My Hijackthis log, does anybody understand it?

It takes six months to a year of part-time study to qualify to read a HijackThis log properly and know how to remove spyware safely. Seeking unqualified help is a sure way to make your situation a lot worse. Go to a specialist malware removal forum, such as:

http://www.malwarebytes.org/forums/

http://malwareremoval.com

http://bleepingcomputer.com
 
Vote for this answer ::  
RE: My Hijackthis log, does anybody understand it?

There is NO keylogger or signs of malware.

You are running TWO antivirus programs McAfee and AVG.

This will lead to system instability and false positive readings.

Personally I would remove both and replace with Avast, the choice is yours, but one has to go.

Uninstall with RevoUninstaller:

http://www.download.com/Revo-Uninstaller...

It's faster and better than add / remove applet.

When you run it highlight the item then select uninstall in next window select Advanced and click Next, follow prompts when uninstalled it will scan registry and drive for leftover files / folders,click + sign to expand all results and tick ONLY the bold items and follow prompts.



Avast anti-virus which better definitions, anti-spyware and anti-rootkit built in, faster and more reliable:

http://www.download.com/Avast-Home-Editi...

Setup Guide:

http://tinyurl.com/5lxy24

AV Comparison:

http://www.virusbtn.com/news/2008/09_02

http://www.av-comparatives.org/
 
Vote for this answer ::  
RE: My Hijackthis log, does anybody understand it?

Post your log file to http://www.hijackthis.de/en
 
Vote for this answer ::  
RE: My Hijackthis log, does anybody understand it?

Its just telling you the processes that are running currently on your computer...

According to my knowledge, everything seems fine
 
Vote for this answer ::  
Update Alert Setting